Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Guide

How to build a penetration test plan that keeps the fee fixed

A penetration test plan sets out what will be tested, how, when and by whom. So it is the document that keeps a fixed fee fixed, because vague edges are how budgets drift 40 to 60 percent over.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Penetration test plan: write the scope, agree the rules and fix the dates

What a penetration test plan contains

Every plan we sign covers the same core sections. Therefore nothing important is left to assumption.

  • Scope written both ways: included and excluded
  • Rules of engagement and safe limits
  • Testing windows and time zones
  • Contacts on both sides, including out of hours
  • Deliverables and the retest window

Writing scope both ways

List what is in, but also list what is out. For example, a third-party payment page you do not own must be excluded, because you cannot authorise testing on it.

Penetration test plan checklist

Tick each section you can already fill in. The rest we work out together in writing.

Your result appears here as you tick, so you can see what is still open.

Rules of engagement in the penetration test plan

Rules decide how far testing goes. So they cover destructive tests, social engineering, data handling and what happens if a critical issue appears.

RuleTypical setting
Destructive testsNot without separate written approval.
Critical findingsReported the same day, so you can act.
Production dataViewed only to prove access, never kept.
Stop procedureA named contact can pause testing at once.

Timing and dependencies

Fix the dates around releases and audits. Also allow time after testing for fixes and the retest. As a guide, testing runs three to ten days, and the report follows about ten working days later.

How the plan changes the quote

A clear plan lets us quote a fixed fee with stated hours. If the scope genuinely changes, we re-quote in writing and wait for approval, so nothing lands on an invoice unannounced. The structure follows NIST SP 800-115.

Penetration test plan questions

Who writes the penetration test plan?

We draft it from your answers, then you review and sign it before testing.

Can the plan change mid-test?

Only in writing. If scope changes, we re-quote first.

Is a penetration test plan the same as rules of engagement?

The rules are one part of it. The plan also covers scope, dates and deliverables.

Do we need a call to plan it?

No. Everything runs in writing, so both sides hold the same record.

Related guides

Start your penetration test plan in writing

Answer four questions on our home page. We draft the plan and a fixed fee, so you can review both before signing.

Get my fixed-fee quote